Forum Discussion
Hille_de_Graaf_
Nimbostratus
Oct 24, 2007bypass a CRL with an invalid date
Hi,
We are using client certificates and a CRL (Certificate Revocation List) to check wether the client certificate is revocated.
Every night we are loading a new CRL from our provider ...
Arley_6164
Nimbostratus
May 26, 2009Posted By capmblade on 11/09/2007 10:43 AM
Hello Hille,
I tested your rule with an expired CRL and for me anyway, it DOES allow the traffic through. I see the following three messages:
"Found CRL is expired -- revoking all certificates until current CRL is available."
Rule crltest : ClientSSL_Client handshake status: CRL has expired
Rule crltest : CRL date is not valid, but you may continue
I also tested your rule with a revoked certificate and it redirects to "certerror.htm"
Do you not see the "you may continue" message when you run your rule?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
